Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State
Description
Published to the GitHub Advisory Database
May 14, 2026
Reviewed
May 14, 2026
Published by the National Vulnerability Database
Jun 9, 2026
Last updated
Jun 9, 2026
Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks.
You are vulnerable if all of the following is true:
nameattribute on an input or button element within that formReferences